Skip to content

fix(react): mapDensity abstains on non-string rowHeight instead of coercing it (#4459) - #4469

Merged
yinlianghui merged 2 commits into
mainfrom
claude/issue-4459-bridge-nonstring-guard
Aug 12, 2026
Merged

fix(react): mapDensity abstains on non-string rowHeight instead of coercing it (#4459)#4469
yinlianghui merged 2 commits into
mainfrom
claude/issue-4459-bridge-nonstring-guard

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Closes #4459

The defect

mapDensity in packages/react/src/spec-bridge/bridges/list-view.ts opened with a truthiness guard:

if (!rowHeight) return undefined;

That rejects only falsy values. Any truthy non-string walked straight past it into a lookup that coerces its key — both Object.prototype.hasOwnProperty.call and the table index run String(...). So a value that is not a string at all still selected a density, while the core twin (packages/core/src/utils/normalize-list-view.ts:83), which opens with a type guard, abstained:

rowHeight core bridge (before) bridge (after)
['compact'] undefined 'compact' undefined
new String('compact') undefined 'compact' undefined
{ toString: () => 'compact' } undefined 'compact' undefined

Note the direction against #4442: that leak returned a function, visibly wrong to everything downstream. This one returned a legitimate-looking 'compact' that nothing downstream can tell apart from an authored density — and bridgeListView writes the key under if (density), so it was not merely returned, it was stored on the SchemaNode.

The fix

One line — core's opening guard, mirrored:

if (typeof rowHeight !== 'string') return undefined;

The type guard subsumes the one it replaces (undefined, null, 0 and false are all non-strings), and the #4457 hasOwnProperty guard is kept as-is after it. '' keeps its answer while changing route: falsy before, so it never reached the table; a string now, so it passes this guard and is refused one line later because it is not one of the five spec keys. Pinned explicitly rather than argued.

Red-first

The extended pin was run against the unfixed source first. It went red, verbatim:

 Test Files  1 failed (1)
      Tests  7 failed | 31 passed (38)

 > non-string row heights — both abstain (#4459) > neither surface invents a density for the array ['compact']
AssertionError: expected 'compact' to be undefined

- Expected:
undefined

+ Received:
"compact"

 > off-spec row heights — both abstain > agrees for every off-spec input without either side being read first
AssertionError: expected undefined to be 'compact' // Object.is equality

All 7 failures came from the three coercing non-strings (the two it.each blocks plus the invariant loop). The non-coercing rows — 42, true, 0, false, null, undefined — passed before the fix too, which is the honest reading: they are completeness rows, not regression rows. They are pinned anyway because this change replaces the truthiness guard rather than adding to it, so the new guard has to keep catching everything the old one caught.

After the fix, the same file: Tests 38 passed (38). The 31 pre-existing cases — all five spec row heights, and the string off-spec plus prototype-member families from #4447/#4457 — stayed green throughout, in both directions.

Verification

Command Result
pnpm exec vitest run packages/react/src/spec-bridge/__tests__/RowHeightDensityAgreement.test.ts 38 passed (38)
pnpm exec vitest run packages/react/ --maxWorkers=2 39 files, 555 passed (555)
pnpm --filter @object-ui/react type-check green (both tsc --noEmit and tsc -p tsconfig.test.json)
eslint on both changed files 0 errors
node scripts/check-changeset-presence.mjs green

Emitted types were diffed pre/post build: no .d.ts moved (mapDensity is module-local; the only dist change is the guard line and its comment in list-view.js), so the changeset is patch for @object-ui/react per the ruling.

Surface: packages/react/src/spec-bridge/** plus one changeset. Nothing else.


Generated by Claude Code

…ercing it (#4459)

`mapDensity` opened with a truthiness guard, so any truthy non-string survived
it and was then coerced into a lookup key -- both `hasOwnProperty.call` and the
table index run `String(...)`. `['compact']`, a boxed `String('compact')` and
`{ toString: () => 'compact' }` therefore each selected a real density, while
core's `rowHeightToDensityMode` -- which opens with `typeof rowHeight !==
'string'` -- abstained for the same input.

Replace the truthiness guard with core's type guard. The type guard subsumes
the old one (undefined/null/0/false are all non-strings) and `''` keeps its
answer by a different route: a string now, refused one line later by the
existing `hasOwnProperty` guard because it is not one of the five spec keys.

Extends the agreement pin with the non-string family, closing the gap between
what the file's title claims and what it pinned -- both prior off-spec families
are strings. Red-first: 7 failures pre-fix, all three coercing non-strings;
38/38 green after.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercel Bot commented Aug 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Aug 12, 2026 1:56pm

Request Review

The #4459 note said core's twin lives in the "same file". It does not --
`rowHeightToDensityMode` is in `@object-ui/core`
(`packages/core/src/utils/normalize-list-view.ts:83`). Comment-only; cite the
path the way the rest of this file's notes do.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 24.7 KB 350 KB
Entry file index-DVgqBKUS.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 9.56KB 3.59KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 8.92KB 3.41KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.13KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.64KB 2.21KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 26.07KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.65KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 489.32KB 108.45KB
core (index.js) 2.99KB 1.14KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 153.42KB 41.19KB
fields (index.js) 228.99KB 56.82KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 3.35KB 1.38KB
i18n (pickLocalized.js) 3.69KB 1.73KB
i18n (provider.js) 23.12KB 7.62KB
i18n (useDisplayLocale.js) 2.33KB 1.20KB
i18n (useObjectLabel.js) 27.59KB 6.63KB
i18n (useSafeTranslation.js) 7.77KB 3.13KB
layout (index.js) 38.98KB 10.85KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.75KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.75KB 3.80KB
plugin-calendar (index.js) 45.24KB 12.46KB
plugin-charts (index.js) 62.01KB 17.63KB
plugin-chatbot (index.js) 181.17KB 43.03KB
plugin-dashboard (index.js) 120.75KB 31.38KB
plugin-designer (index.js) 212.58KB 42.83KB
plugin-detail (index.js) 239.03KB 59.77KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 114.58KB 27.68KB
plugin-gantt (index.js) 164.14KB 39.98KB
plugin-grid (index.js) 188.13KB 50.00KB
plugin-kanban (index.js) 48.62KB 13.42KB
plugin-list (index.js) 110.20KB 26.79KB
plugin-map (index.js) 18.16KB 5.81KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 40.99KB 10.74KB
plugin-timeline (index.js) 26.21KB 7.52KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.08KB 20.55KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 23.73KB 7.96KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.23KB 0.66KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 4.47KB 2.03KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 3.05KB 1.52KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Copy link
Copy Markdown
Collaborator Author

ACCEPT — step-7 复核 by PM session session_017Qqyix2QcnpUC9XeYVDzx3 (focused review).

  • Red-first verbatim and honest: 7 of 38 red, all seven driven by the three genuinely-coercing inputs (['compact'], new String('compact'), {toString}), 31 pre-existing cases green throughout. The completeness rows (number/boolean/falsy) correctly labelled as guard-replacement assertions — they carry "the new guard keeps catching everything the truthiness guard caught", and reporting that they were already green pre-fix is exactly the null-result honesty this seat wants.
  • Empty-string case pinned as "different route, same answer" through all three surfaces — the one subtle behavior of swapping a truthiness guard for a type guard, handled explicitly.
  • .d.ts byte-identical (with the dev's own false-alarm diff flag caught and corrected) → patch stands. Comment-only second commit for a self-caught citation error, no force-push — correct.
  • CI 17 success / 3 conditional skips / 0 failures, mergeable clean. Surface exactly 3 files.

rowHeight family is now fully closed on BOTH input families: core, bridge, ListView, and standalone ObjectGrid give one answer on off-spec strings (#4447/#4457/#4458), and core + bridge agree on non-strings (this PR). Flipping ready + arming auto-merge. Slot not refilled — per the current maintainer instruction this wave winds down after #4456.


Generated by Claude Code


Generated by Claude Code

@yinlianghui
yinlianghui marked this pull request as ready for review August 12, 2026 14:08
@yinlianghui
yinlianghui added this pull request to the merge queue Aug 12, 2026
Merged via the queue into main with commit 47f551b Aug 12, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4459-bridge-nonstring-guard branch August 12, 2026 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

finding(react): mapDensity still coerces a non-string rowHeight to a density, where the core twin abstains

2 participants